SEBI · Circular

Clarifications to Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities

SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184

In short
SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184 is the first Clarifications circular to the CSCRF, issued on 31 December 2024. It answered the opening round of queries from regulated entities on the framework issued four months earlier, and is the first of five circulars that have since amended CSCRF.

The record

ReferenceSEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/184
Issued bySecurities and Exchange Board of India (SEBI)
Instrument typeCircular
Date of issue31 December 2024
StatusIn force
BindsAnswered the first round of queries from regulated entities.
Dates it setsIn effect on issue. The instrument sets no further dates.
CSCRF clarifications, December 2024 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Answers the first round of queries raised by regulated entities on CSCRF.
  • Issued 31 December 2024, four months after the framework itself.
  • The first of five circulars amending or clarifying CSCRF between December 2024 and August 2025.

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • SEBI CSCRF SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113SEBI regulated entities, graded into five categories with obligations scaled to the category.
  • CSCRF clarifications, April 2025 SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/60Revised the CSCRF categorisation criteria and thresholds, including for Depository Participants.
  • First extension, March 2025 SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2025/45Moved the CSCRF deadline to 30 June 2025, excluding MIIs, KRAs and QRTAs.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating The SEBI CSCRF compliance guide